2 Unix SMB/CIFS implementation.
6 Copyright (C) Gerald Carter 2006
7 Copyright (C) Guenther Deschner 2007-2008
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #define DSGETDCNAME_FMT "DSGETDCNAME/DOMAIN/%s"
27 #define DSGETDCNAME_CACHE_TTL 60*15
29 struct ip_service_name
{
30 struct sockaddr_storage ss
;
35 /****************************************************************
36 ****************************************************************/
38 void debug_dsdcinfo_flags(int lvl
, uint32_t flags
)
40 DEBUG(lvl
,("debug_dsdcinfo_flags: 0x%08x\n\t", flags
));
42 if (flags
& DS_FORCE_REDISCOVERY
)
43 DEBUGADD(lvl
,("DS_FORCE_REDISCOVERY "));
44 if (flags
& 0x000000002)
45 DEBUGADD(lvl
,("0x00000002 "));
46 if (flags
& 0x000000004)
47 DEBUGADD(lvl
,("0x00000004 "));
48 if (flags
& 0x000000008)
49 DEBUGADD(lvl
,("0x00000008 "));
50 if (flags
& DS_DIRECTORY_SERVICE_REQUIRED
)
51 DEBUGADD(lvl
,("DS_DIRECTORY_SERVICE_REQUIRED "));
52 if (flags
& DS_DIRECTORY_SERVICE_PREFERRED
)
53 DEBUGADD(lvl
,("DS_DIRECTORY_SERVICE_PREFERRED "));
54 if (flags
& DS_GC_SERVER_REQUIRED
)
55 DEBUGADD(lvl
,("DS_GC_SERVER_REQUIRED "));
56 if (flags
& DS_PDC_REQUIRED
)
57 DEBUGADD(lvl
,("DS_PDC_REQUIRED "));
58 if (flags
& DS_BACKGROUND_ONLY
)
59 DEBUGADD(lvl
,("DS_BACKGROUND_ONLY "));
60 if (flags
& DS_IP_REQUIRED
)
61 DEBUGADD(lvl
,("DS_IP_REQUIRED "));
62 if (flags
& DS_KDC_REQUIRED
)
63 DEBUGADD(lvl
,("DS_KDC_REQUIRED "));
64 if (flags
& DS_TIMESERV_REQUIRED
)
65 DEBUGADD(lvl
,("DS_TIMESERV_REQUIRED "));
66 if (flags
& DS_WRITABLE_REQUIRED
)
67 DEBUGADD(lvl
,("DS_WRITABLE_REQUIRED "));
68 if (flags
& DS_GOOD_TIMESERV_PREFERRED
)
69 DEBUGADD(lvl
,("DS_GOOD_TIMESERV_PREFERRED "));
70 if (flags
& DS_AVOID_SELF
)
71 DEBUGADD(lvl
,("DS_AVOID_SELF "));
72 if (flags
& DS_ONLY_LDAP_NEEDED
)
73 DEBUGADD(lvl
,("DS_ONLY_LDAP_NEEDED "));
74 if (flags
& DS_IS_FLAT_NAME
)
75 DEBUGADD(lvl
,("DS_IS_FLAT_NAME "));
76 if (flags
& DS_IS_DNS_NAME
)
77 DEBUGADD(lvl
,("DS_IS_DNS_NAME "));
78 if (flags
& 0x00040000)
79 DEBUGADD(lvl
,("0x00040000 "));
80 if (flags
& 0x00080000)
81 DEBUGADD(lvl
,("0x00080000 "));
82 if (flags
& 0x00100000)
83 DEBUGADD(lvl
,("0x00100000 "));
84 if (flags
& 0x00200000)
85 DEBUGADD(lvl
,("0x00200000 "));
86 if (flags
& 0x00400000)
87 DEBUGADD(lvl
,("0x00400000 "));
88 if (flags
& 0x00800000)
89 DEBUGADD(lvl
,("0x00800000 "));
90 if (flags
& 0x01000000)
91 DEBUGADD(lvl
,("0x01000000 "));
92 if (flags
& 0x02000000)
93 DEBUGADD(lvl
,("0x02000000 "));
94 if (flags
& 0x04000000)
95 DEBUGADD(lvl
,("0x04000000 "));
96 if (flags
& 0x08000000)
97 DEBUGADD(lvl
,("0x08000000 "));
98 if (flags
& 0x10000000)
99 DEBUGADD(lvl
,("0x10000000 "));
100 if (flags
& 0x20000000)
101 DEBUGADD(lvl
,("0x20000000 "));
102 if (flags
& DS_RETURN_DNS_NAME
)
103 DEBUGADD(lvl
,("DS_RETURN_DNS_NAME "));
104 if (flags
& DS_RETURN_FLAT_NAME
)
105 DEBUGADD(lvl
,("DS_RETURN_FLAT_NAME "));
107 DEBUGADD(lvl
,("\n"));
110 /****************************************************************
111 ****************************************************************/
113 static char *dsgetdcname_cache_key(TALLOC_CTX
*mem_ctx
, const char *domain
)
115 if (!mem_ctx
|| !domain
) {
119 return talloc_asprintf_strupper_m(mem_ctx
, DSGETDCNAME_FMT
, domain
);
122 /****************************************************************
123 ****************************************************************/
125 static NTSTATUS
dsgetdcname_cache_delete(TALLOC_CTX
*mem_ctx
,
126 const char *domain_name
)
130 if (!gencache_init()) {
131 return NT_STATUS_INTERNAL_DB_ERROR
;
134 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
136 return NT_STATUS_NO_MEMORY
;
139 if (!gencache_del(key
)) {
140 return NT_STATUS_UNSUCCESSFUL
;
146 /****************************************************************
147 ****************************************************************/
149 static NTSTATUS
dsgetdcname_cache_store(TALLOC_CTX
*mem_ctx
,
150 const char *domain_name
,
151 struct netr_DsRGetDCNameInfo
*info
)
157 enum ndr_err_code ndr_err
;
159 if (!gencache_init()) {
160 return NT_STATUS_INTERNAL_DB_ERROR
;
163 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
165 return NT_STATUS_NO_MEMORY
;
168 expire_time
= time(NULL
) + DSGETDCNAME_CACHE_TTL
;
170 ndr_err
= ndr_push_struct_blob(&blob
, mem_ctx
, info
,
171 (ndr_push_flags_fn_t
)ndr_push_netr_DsRGetDCNameInfo
);
172 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
173 return ndr_map_error2ntstatus(ndr_err
);
176 if (gencache_lock_entry(key
) != 0) {
177 data_blob_free(&blob
);
178 return NT_STATUS_LOCK_NOT_GRANTED
;
181 ret
= gencache_set_data_blob(key
, &blob
, expire_time
);
182 data_blob_free(&blob
);
184 gencache_unlock_entry(key
);
186 return ret
? NT_STATUS_OK
: NT_STATUS_UNSUCCESSFUL
;
189 /****************************************************************
190 ****************************************************************/
192 static NTSTATUS
dsgetdcname_cache_refresh(TALLOC_CTX
*mem_ctx
,
193 const char *domain_name
,
194 struct GUID
*domain_guid
,
196 const char *site_name
,
197 struct netr_DsRGetDCNameInfo
*info
)
199 uint32_t nt_version
= NETLOGON_VERSION_1
;
201 /* check if matching entry is older then 15 minutes, if yes, send
202 * CLDAP/MAILSLOT ping again and store the cached data */
204 if (ads_cldap_netlogon(mem_ctx
, info
->dc_unc
,
205 info
->domain_name
, &nt_version
, NULL
)) {
207 dsgetdcname_cache_delete(mem_ctx
, domain_name
);
209 return dsgetdcname_cache_store(mem_ctx
,
214 return NT_STATUS_INVALID_NETWORK_RESPONSE
;
217 /****************************************************************
218 ****************************************************************/
220 static uint32_t get_cldap_reply_server_flags(union nbt_cldap_netlogon
*r
,
223 switch (nt_version
& 0x000000ff) {
229 return r
->logon3
.server_type
;
234 return r
->logon5
.server_type
;
243 return r
->logon13
.server_type
;
245 return r
->logon29
.server_type
;
249 /****************************************************************
250 ****************************************************************/
252 #define RETURN_ON_FALSE(x) if (!x) return false;
254 static bool check_cldap_reply_required_flags(uint32_t ret_flags
,
257 if (ret_flags
== 0) {
261 if (req_flags
& DS_PDC_REQUIRED
)
262 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_PDC
);
264 if (req_flags
& DS_GC_SERVER_REQUIRED
)
265 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_GC
);
267 if (req_flags
& DS_ONLY_LDAP_NEEDED
)
268 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_LDAP
);
270 if ((req_flags
& DS_DIRECTORY_SERVICE_REQUIRED
) ||
271 (req_flags
& DS_DIRECTORY_SERVICE_PREFERRED
))
272 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_DS
);
274 if (req_flags
& DS_KDC_REQUIRED
)
275 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_KDC
);
277 if (req_flags
& DS_TIMESERV_REQUIRED
)
278 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_TIMESERV
);
280 if (req_flags
& DS_WRITABLE_REQUIRED
)
281 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_WRITABLE
);
286 /****************************************************************
287 ****************************************************************/
289 static NTSTATUS
dsgetdcname_cache_fetch(TALLOC_CTX
*mem_ctx
,
290 const char *domain_name
,
291 struct GUID
*domain_guid
,
293 const char *site_name
,
294 struct netr_DsRGetDCNameInfo
**info_p
,
299 enum ndr_err_code ndr_err
;
300 struct netr_DsRGetDCNameInfo
*info
;
302 if (!gencache_init()) {
303 return NT_STATUS_INTERNAL_DB_ERROR
;
306 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
308 return NT_STATUS_NO_MEMORY
;
311 if (!gencache_get_data_blob(key
, &blob
, expired
)) {
312 return NT_STATUS_OBJECT_NAME_NOT_FOUND
;
315 info
= TALLOC_ZERO_P(mem_ctx
, struct netr_DsRGetDCNameInfo
);
317 return NT_STATUS_NO_MEMORY
;
320 ndr_err
= ndr_pull_struct_blob(&blob
, mem_ctx
, info
,
321 (ndr_pull_flags_fn_t
)ndr_pull_netr_DsRGetDCNameInfo
);
323 data_blob_free(&blob
);
324 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
325 dsgetdcname_cache_delete(mem_ctx
, domain_name
);
326 return ndr_map_error2ntstatus(ndr_err
);
329 if (DEBUGLEVEL
>= 10) {
330 NDR_PRINT_DEBUG(netr_DsRGetDCNameInfo
, info
);
334 if (!check_cldap_reply_required_flags(info
->dc_flags
, flags
)) {
335 DEBUG(10,("invalid flags\n"));
336 return NT_STATUS_INVALID_PARAMETER
;
339 if ((flags
& DS_IP_REQUIRED
) &&
340 (info
->dc_address_type
!= DS_ADDRESS_TYPE_INET
)) {
341 return NT_STATUS_INVALID_PARAMETER_MIX
;
349 /****************************************************************
350 ****************************************************************/
352 static NTSTATUS
dsgetdcname_cached(TALLOC_CTX
*mem_ctx
,
353 const char *domain_name
,
354 struct GUID
*domain_guid
,
356 const char *site_name
,
357 struct netr_DsRGetDCNameInfo
**info
)
360 bool expired
= false;
362 status
= dsgetdcname_cache_fetch(mem_ctx
, domain_name
, domain_guid
,
363 flags
, site_name
, info
, &expired
);
364 if (!NT_STATUS_IS_OK(status
)) {
365 DEBUG(10,("dsgetdcname_cached: cache fetch failed with: %s\n",
367 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
370 if (flags
& DS_BACKGROUND_ONLY
) {
375 status
= dsgetdcname_cache_refresh(mem_ctx
, domain_name
,
378 if (!NT_STATUS_IS_OK(status
)) {
386 /****************************************************************
387 ****************************************************************/
389 static bool check_allowed_required_flags(uint32_t flags
)
391 uint32_t return_type
= flags
& (DS_RETURN_FLAT_NAME
|DS_RETURN_DNS_NAME
);
392 uint32_t offered_type
= flags
& (DS_IS_FLAT_NAME
|DS_IS_DNS_NAME
);
393 uint32_t query_type
= flags
& (DS_BACKGROUND_ONLY
|DS_FORCE_REDISCOVERY
);
395 /* FIXME: check for DSGETDC_VALID_FLAGS and check for excluse bits
396 * (DS_PDC_REQUIRED, DS_KDC_REQUIRED, DS_GC_SERVER_REQUIRED) */
398 debug_dsdcinfo_flags(10, flags
);
400 if (return_type
== (DS_RETURN_FLAT_NAME
|DS_RETURN_DNS_NAME
)) {
404 if (offered_type
== (DS_IS_DNS_NAME
|DS_IS_FLAT_NAME
)) {
408 if (query_type
== (DS_BACKGROUND_ONLY
|DS_FORCE_REDISCOVERY
)) {
413 if ((flags
& DS_RETURN_DNS_NAME
) && (!(flags
& DS_IP_REQUIRED
))) {
414 printf("gd: here5 \n");
421 /****************************************************************
422 ****************************************************************/
424 static NTSTATUS
discover_dc_netbios(TALLOC_CTX
*mem_ctx
,
425 const char *domain_name
,
427 struct ip_service_name
**returned_dclist
,
431 enum nbt_name_type name_type
= NBT_NAME_LOGON
;
432 struct ip_service
*iplist
;
434 struct ip_service_name
*dclist
= NULL
;
437 *returned_dclist
= NULL
;
440 if (lp_disable_netbios()) {
441 return NT_STATUS_NOT_SUPPORTED
;
444 if (flags
& DS_PDC_REQUIRED
) {
445 name_type
= NBT_NAME_PDC
;
448 status
= internal_resolve_name(domain_name
, name_type
, NULL
,
450 "lmhosts wins bcast");
451 if (!NT_STATUS_IS_OK(status
)) {
452 DEBUG(10,("discover_dc_netbios: failed to find DC\n"));
456 dclist
= TALLOC_ZERO_ARRAY(mem_ctx
, struct ip_service_name
, count
);
458 return NT_STATUS_NO_MEMORY
;
461 for (i
=0; i
<count
; i
++) {
463 char addr
[INET6_ADDRSTRLEN
];
464 struct ip_service_name
*r
= &dclist
[i
];
466 print_sockaddr(addr
, sizeof(addr
),
469 r
->ss
= iplist
[i
].ss
;
470 r
->port
= iplist
[i
].port
;
471 r
->hostname
= talloc_strdup(mem_ctx
, addr
);
473 return NT_STATUS_NO_MEMORY
;
478 *returned_dclist
= dclist
;
479 *returned_count
= count
;
484 /****************************************************************
485 ****************************************************************/
487 static NTSTATUS
discover_dc_dns(TALLOC_CTX
*mem_ctx
,
488 const char *domain_name
,
489 struct GUID
*domain_guid
,
491 const char *site_name
,
492 struct ip_service_name
**returned_dclist
,
497 struct dns_rr_srv
*dcs
= NULL
;
500 struct ip_service_name
*dclist
= NULL
;
503 if (flags
& DS_PDC_REQUIRED
) {
504 status
= ads_dns_query_pdc(mem_ctx
, domain_name
,
506 } else if (flags
& DS_GC_SERVER_REQUIRED
) {
507 status
= ads_dns_query_gcs(mem_ctx
, domain_name
, site_name
,
509 } else if (flags
& DS_KDC_REQUIRED
) {
510 status
= ads_dns_query_kdcs(mem_ctx
, domain_name
, site_name
,
512 } else if (flags
& DS_DIRECTORY_SERVICE_REQUIRED
) {
513 status
= ads_dns_query_dcs(mem_ctx
, domain_name
, site_name
,
515 } else if (domain_guid
) {
516 status
= ads_dns_query_dcs_guid(mem_ctx
, domain_name
,
517 domain_guid
, &dcs
, &numdcs
);
519 status
= ads_dns_query_dcs(mem_ctx
, domain_name
, site_name
,
523 if (!NT_STATUS_IS_OK(status
)) {
528 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
531 for (i
=0;i
<numdcs
;i
++) {
532 numaddrs
+= MAX(dcs
[i
].num_ips
,1);
535 dclist
= TALLOC_ZERO_ARRAY(mem_ctx
,
536 struct ip_service_name
,
539 return NT_STATUS_NO_MEMORY
;
542 /* now unroll the list of IP addresses */
548 while ((i
< numdcs
) && (count
< numaddrs
)) {
550 struct ip_service_name
*r
= &dclist
[count
];
552 r
->port
= dcs
[count
].port
;
553 r
->hostname
= dcs
[count
].hostname
;
555 if (!(flags
& DS_IP_REQUIRED
)) {
560 /* If we don't have an IP list for a name, lookup it up */
563 interpret_string_addr(&r
->ss
, dcs
[i
].hostname
, 0);
567 /* use the IP addresses from the SRV sresponse */
569 if (j
>= dcs
[i
].num_ips
) {
575 r
->ss
= dcs
[i
].ss_s
[j
];
579 /* make sure it is a valid IP. I considered checking the
580 * negative connection cache, but this is the wrong place for
581 * it. Maybe only as a hac. After think about it, if all of
582 * the IP addresses retuend from DNS are dead, what hope does a
583 * netbios name lookup have? The standard reason for falling
584 * back to netbios lookups is that our DNS server doesn't know
585 * anything about the DC's -- jerry */
587 if (!is_zero_addr(&r
->ss
)) {
593 *returned_dclist
= dclist
;
594 *return_count
= count
;
600 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
603 /****************************************************************
604 ****************************************************************/
606 static NTSTATUS
make_domain_controller_info(TALLOC_CTX
*mem_ctx
,
608 const char *dc_address
,
609 uint32_t dc_address_type
,
610 const struct GUID
*domain_guid
,
611 const char *domain_name
,
612 const char *forest_name
,
614 const char *dc_site_name
,
615 const char *client_site_name
,
616 struct netr_DsRGetDCNameInfo
**info_out
)
618 struct netr_DsRGetDCNameInfo
*info
;
620 info
= TALLOC_ZERO_P(mem_ctx
, struct netr_DsRGetDCNameInfo
);
621 NT_STATUS_HAVE_NO_MEMORY(info
);
624 info
->dc_unc
= talloc_strdup(mem_ctx
, dc_unc
);
625 NT_STATUS_HAVE_NO_MEMORY(info
->dc_unc
);
629 info
->dc_address
= talloc_strdup(mem_ctx
, dc_address
);
630 NT_STATUS_HAVE_NO_MEMORY(info
->dc_address
);
633 info
->dc_address_type
= dc_address_type
;
636 info
->domain_guid
= *domain_guid
;
640 info
->domain_name
= talloc_strdup(mem_ctx
, domain_name
);
641 NT_STATUS_HAVE_NO_MEMORY(info
->domain_name
);
645 info
->forest_name
= talloc_strdup(mem_ctx
, forest_name
);
646 NT_STATUS_HAVE_NO_MEMORY(info
->forest_name
);
647 flags
|= DS_DNS_FOREST
;
650 info
->dc_flags
= flags
;
653 info
->dc_site_name
= talloc_strdup(mem_ctx
, dc_site_name
);
654 NT_STATUS_HAVE_NO_MEMORY(info
->dc_site_name
);
657 if (client_site_name
) {
658 info
->client_site_name
= talloc_strdup(mem_ctx
,
660 NT_STATUS_HAVE_NO_MEMORY(info
->client_site_name
);
668 /****************************************************************
669 ****************************************************************/
671 static NTSTATUS
make_dc_info_from_cldap_reply(TALLOC_CTX
*mem_ctx
,
673 struct sockaddr_storage
*ss
,
675 union nbt_cldap_netlogon
*r
,
676 struct netr_DsRGetDCNameInfo
**info
)
678 const char *dc_hostname
, *dc_domain_name
;
679 const char *dc_address
= NULL
;
680 const char *dc_forest
= NULL
;
681 uint32_t dc_address_type
= 0;
682 uint32_t dc_flags
= 0;
683 struct GUID
*dc_domain_guid
= NULL
;
684 const char *dc_server_site
= NULL
;
685 const char *dc_client_site
= NULL
;
687 char addr
[INET6_ADDRSTRLEN
];
689 print_sockaddr(addr
, sizeof(addr
), ss
);
691 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s", addr
);
692 NT_STATUS_HAVE_NO_MEMORY(dc_address
);
693 dc_address_type
= DS_ADDRESS_TYPE_INET
;
695 switch (nt_version
& 0x000000ff) {
697 return NT_STATUS_INVALID_PARAMETER
;
699 dc_hostname
= r
->logon1
.pdc_name
;
700 dc_domain_name
= r
->logon1
.domain_name
;
701 if (flags
& DS_PDC_REQUIRED
) {
702 dc_flags
= NBT_SERVER_WRITABLE
| NBT_SERVER_PDC
;
707 switch (flags
& 0xf0000000) {
708 case DS_RETURN_FLAT_NAME
:
709 dc_hostname
= r
->logon3
.pdc_name
;
710 dc_domain_name
= r
->logon3
.domain_name
;
712 case DS_RETURN_DNS_NAME
:
714 dc_hostname
= r
->logon3
.pdc_dns_name
;
715 dc_domain_name
= r
->logon3
.dns_domain
;
716 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
720 dc_flags
|= r
->logon3
.server_type
;
721 dc_forest
= r
->logon3
.forest
;
722 dc_domain_guid
= &r
->logon3
.domain_uuid
;
729 switch (flags
& 0xf0000000) {
730 case DS_RETURN_FLAT_NAME
:
731 dc_hostname
= r
->logon5
.pdc_name
;
732 dc_domain_name
= r
->logon5
.domain
;
734 case DS_RETURN_DNS_NAME
:
736 dc_hostname
= r
->logon5
.pdc_dns_name
;
737 dc_domain_name
= r
->logon5
.dns_domain
;
738 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
742 dc_flags
|= r
->logon5
.server_type
;
743 dc_forest
= r
->logon5
.forest
;
744 dc_domain_guid
= &r
->logon5
.domain_uuid
;
745 dc_server_site
= r
->logon5
.server_site
;
746 dc_client_site
= r
->logon5
.client_site
;
757 switch (flags
& 0xf0000000) {
758 case DS_RETURN_FLAT_NAME
:
759 dc_hostname
= r
->logon13
.pdc_name
;
760 dc_domain_name
= r
->logon13
.domain
;
762 case DS_RETURN_DNS_NAME
:
764 dc_hostname
= r
->logon13
.pdc_dns_name
;
765 dc_domain_name
= r
->logon13
.dns_domain
;
766 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
770 dc_flags
|= r
->logon13
.server_type
;
771 dc_forest
= r
->logon13
.forest
;
772 dc_domain_guid
= &r
->logon13
.domain_uuid
;
773 dc_server_site
= r
->logon13
.server_site
;
774 dc_client_site
= r
->logon13
.client_site
;
778 switch (flags
& 0xf0000000) {
779 case DS_RETURN_FLAT_NAME
:
780 dc_hostname
= r
->logon29
.pdc_name
;
781 dc_domain_name
= r
->logon29
.domain
;
783 case DS_RETURN_DNS_NAME
:
785 dc_hostname
= r
->logon29
.pdc_dns_name
;
786 dc_domain_name
= r
->logon29
.dns_domain
;
787 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
791 dc_flags
|= r
->logon29
.server_type
;
792 dc_forest
= r
->logon29
.forest
;
793 dc_domain_guid
= &r
->logon29
.domain_uuid
;
794 dc_server_site
= r
->logon29
.server_site
;
795 dc_client_site
= r
->logon29
.client_site
;
800 return make_domain_controller_info(mem_ctx
,
813 /****************************************************************
814 ****************************************************************/
816 static uint32_t map_ds_flags_to_nt_version(uint32_t flags
)
818 uint32_t nt_version
= 0;
820 if (flags
& DS_PDC_REQUIRED
) {
821 nt_version
|= NETLOGON_VERSION_PDC
;
824 if (flags
& DS_GC_SERVER_REQUIRED
) {
825 nt_version
|= NETLOGON_VERSION_GC
;
828 if (flags
& DS_TRY_NEXTCLOSEST_SITE
) {
829 nt_version
|= NETLOGON_VERSION_WITH_CLOSEST_SITE
;
832 if (flags
& DS_IP_REQUIRED
) {
833 nt_version
|= NETLOGON_VERSION_IP
;
839 /****************************************************************
840 ****************************************************************/
842 static NTSTATUS
process_dc_dns(TALLOC_CTX
*mem_ctx
,
843 const char *domain_name
,
845 struct ip_service_name
*dclist
,
847 struct netr_DsRGetDCNameInfo
**info
)
850 bool valid_dc
= false;
851 union nbt_cldap_netlogon
*r
= NULL
;
852 uint32_t nt_version
= NETLOGON_VERSION_5
|
853 NETLOGON_VERSION_5EX
;
854 uint32_t ret_flags
= 0;
856 nt_version
|= map_ds_flags_to_nt_version(flags
);
858 for (i
=0; i
<num_dcs
; i
++) {
860 DEBUG(10,("LDAP ping to %s\n", dclist
[i
].hostname
));
862 if (ads_cldap_netlogon(mem_ctx
, dclist
[i
].hostname
,
867 ret_flags
= get_cldap_reply_server_flags(r
, nt_version
);
869 if (check_cldap_reply_required_flags(ret_flags
, flags
)) {
879 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
882 return make_dc_info_from_cldap_reply(mem_ctx
, flags
, &dclist
[i
].ss
,
883 nt_version
, r
, info
);
886 /****************************************************************
887 ****************************************************************/
889 static struct event_context
*ev_context(void)
891 static struct event_context
*ctx
;
893 if (!ctx
&& !(ctx
= event_context_init(NULL
))) {
894 smb_panic("Could not init event context");
899 /****************************************************************
900 ****************************************************************/
902 static struct messaging_context
*msg_context(TALLOC_CTX
*mem_ctx
)
904 static struct messaging_context
*ctx
;
906 if (!ctx
&& !(ctx
= messaging_init(mem_ctx
, server_id_self(),
908 smb_panic("Could not init messaging context");
913 /****************************************************************
914 ****************************************************************/
916 static NTSTATUS
process_dc_netbios(TALLOC_CTX
*mem_ctx
,
917 const char *domain_name
,
919 struct ip_service_name
*dclist
,
921 struct netr_DsRGetDCNameInfo
**info
)
923 struct sockaddr_storage ss
;
924 struct ip_service ip_list
;
925 enum nbt_name_type name_type
= NBT_NAME_LOGON
;
928 const char *dc_name
= NULL
;
930 struct messaging_context
*msg_ctx
= msg_context(mem_ctx
);
931 union nbt_cldap_netlogon
*reply
= NULL
;
932 uint32_t nt_version
= NETLOGON_VERSION_1
|
934 NETLOGON_VERSION_5EX_WITH_IP
;
936 if (flags
& DS_PDC_REQUIRED
) {
937 name_type
= NBT_NAME_PDC
;
940 nt_version
|= map_ds_flags_to_nt_version(flags
);
942 DEBUG(10,("process_dc_netbios\n"));
944 for (i
=0; i
<num_dcs
; i
++) {
946 ip_list
.ss
= dclist
[i
].ss
;
949 if (!interpret_string_addr(&ss
, dclist
[i
].hostname
, AI_NUMERICHOST
)) {
950 return NT_STATUS_UNSUCCESSFUL
;
953 if (send_getdc_request(mem_ctx
, msg_ctx
,
954 &dclist
[i
].ss
, domain_name
,
959 for (k
=0; k
<5; k
++) {
960 if (receive_getdc_response(mem_ctx
,
966 namecache_store(dc_name
, NBT_NAME_SERVER
, 1, &ip_list
);
973 if (name_status_find(domain_name
,
979 struct nbt_cldap_netlogon_1 logon1
;
981 reply
= TALLOC_ZERO_P(mem_ctx
, union nbt_cldap_netlogon
);
982 NT_STATUS_HAVE_NO_MEMORY(reply
);
986 nt_version
= NETLOGON_VERSION_1
;
988 logon1
.nt_version
= nt_version
;
989 logon1
.pdc_name
= tmp_dc_name
;
990 logon1
.domain_name
= talloc_strdup_upper(mem_ctx
, domain_name
);
991 NT_STATUS_HAVE_NO_MEMORY(logon1
.domain_name
);
993 reply
->logon1
= logon1
;
995 namecache_store(tmp_dc_name
, NBT_NAME_SERVER
, 1, &ip_list
);
1001 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1005 return make_dc_info_from_cldap_reply(mem_ctx
, flags
, &dclist
[i
].ss
,
1006 nt_version
, reply
, info
);
1009 /****************************************************************
1010 ****************************************************************/
1012 static NTSTATUS
dsgetdcname_rediscover(TALLOC_CTX
*mem_ctx
,
1013 const char *domain_name
,
1014 struct GUID
*domain_guid
,
1016 const char *site_name
,
1017 struct netr_DsRGetDCNameInfo
**info
)
1019 NTSTATUS status
= NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1020 struct ip_service_name
*dclist
= NULL
;
1023 DEBUG(10,("dsgetdcname_rediscover\n"));
1025 if (flags
& DS_IS_FLAT_NAME
) {
1027 status
= discover_dc_netbios(mem_ctx
, domain_name
, flags
,
1029 NT_STATUS_NOT_OK_RETURN(status
);
1031 return process_dc_netbios(mem_ctx
, domain_name
, flags
,
1032 dclist
, num_dcs
, info
);
1035 if (flags
& DS_IS_DNS_NAME
) {
1037 status
= discover_dc_dns(mem_ctx
, domain_name
, domain_guid
,
1038 flags
, site_name
, &dclist
, &num_dcs
);
1039 NT_STATUS_NOT_OK_RETURN(status
);
1041 return process_dc_dns(mem_ctx
, domain_name
, flags
,
1042 dclist
, num_dcs
, info
);
1045 status
= discover_dc_dns(mem_ctx
, domain_name
, domain_guid
, flags
,
1046 site_name
, &dclist
, &num_dcs
);
1048 if (NT_STATUS_IS_OK(status
) && num_dcs
!= 0) {
1050 status
= process_dc_dns(mem_ctx
, domain_name
, flags
, dclist
,
1052 if (NT_STATUS_IS_OK(status
)) {
1057 status
= discover_dc_netbios(mem_ctx
, domain_name
, flags
, &dclist
,
1059 NT_STATUS_NOT_OK_RETURN(status
);
1061 return process_dc_netbios(mem_ctx
, domain_name
, flags
, dclist
,
1065 /********************************************************************
1068 This will be the only public function here.
1069 ********************************************************************/
1071 NTSTATUS
dsgetdcname(TALLOC_CTX
*mem_ctx
,
1072 const char *domain_name
,
1073 struct GUID
*domain_guid
,
1074 const char *site_name
,
1076 struct netr_DsRGetDCNameInfo
**info
)
1078 NTSTATUS status
= NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1079 struct netr_DsRGetDCNameInfo
*myinfo
= NULL
;
1081 DEBUG(10,("dsgetdcname: domain_name: %s, "
1082 "domain_guid: %s, site_name: %s, flags: 0x%08x\n",
1084 domain_guid
? GUID_string(mem_ctx
, domain_guid
) : "(null)",
1089 if (!check_allowed_required_flags(flags
)) {
1090 DEBUG(0,("invalid flags specified\n"));
1091 return NT_STATUS_INVALID_PARAMETER
;
1094 if (flags
& DS_FORCE_REDISCOVERY
) {
1098 status
= dsgetdcname_cached(mem_ctx
, domain_name
, domain_guid
,
1099 flags
, site_name
, &myinfo
);
1100 if (NT_STATUS_IS_OK(status
)) {
1105 if (flags
& DS_BACKGROUND_ONLY
) {
1110 status
= dsgetdcname_rediscover(mem_ctx
, domain_name
,
1111 domain_guid
, flags
, site_name
,
1114 if (NT_STATUS_IS_OK(status
)) {
1115 dsgetdcname_cache_store(mem_ctx
, domain_name
, myinfo
);
1122 /****************************************************************
1123 ****************************************************************/
1125 bool pull_mailslot_cldap_reply(TALLOC_CTX
*mem_ctx
,
1126 const DATA_BLOB
*blob
,
1127 union nbt_cldap_netlogon
*r
,
1128 uint32_t *nt_version
)
1130 enum ndr_err_code ndr_err
;
1131 uint32_t nt_version_query
= ((*nt_version
) & 0x000000ff);
1132 uint16_t command
= 0;
1134 ndr_err
= ndr_pull_struct_blob(blob
, mem_ctx
, &command
,
1135 (ndr_pull_flags_fn_t
)ndr_pull_uint16
);
1136 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1146 DEBUG(1,("got unexpected command: %d (0x%08x)\n",
1151 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1152 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1153 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1157 /* when the caller requested just those nt_version bits that the server
1158 * was able to reply to, we are fine and all done. otherwise we need to
1159 * assume downgraded replies which are painfully parsed here - gd */
1161 if (nt_version_query
& NETLOGON_VERSION_WITH_CLOSEST_SITE
) {
1162 nt_version_query
&= ~NETLOGON_VERSION_WITH_CLOSEST_SITE
;
1164 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1165 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1166 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1169 if (nt_version_query
& NETLOGON_VERSION_5EX_WITH_IP
) {
1170 nt_version_query
&= ~NETLOGON_VERSION_5EX_WITH_IP
;
1172 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1173 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1174 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1177 if (nt_version_query
& NETLOGON_VERSION_5EX
) {
1178 nt_version_query
&= ~NETLOGON_VERSION_5EX
;
1180 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1181 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1182 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1185 if (nt_version_query
& NETLOGON_VERSION_5
) {
1186 nt_version_query
&= ~NETLOGON_VERSION_5
;
1188 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1189 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1190 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1197 if (DEBUGLEVEL
>= 10) {
1198 NDR_PRINT_UNION_DEBUG(nbt_cldap_netlogon
, nt_version_query
, r
);
1201 *nt_version
= nt_version_query
;